Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Remittance.htm

Overview

General Information

Sample Name:Remittance.htm
Analysis ID:800699
MD5:39bb32548e89f58ceb6960e84791979e
SHA1:e70af8a69f739dc0501013a1a9ebb5f4cef552e2
SHA256:bf0f39c7f991c76bbd138e4d74dc9cc402aca673c5edd8b6005dc41faf739208
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Performs DNS queries to domains with low reputation
HTML document with suspicious name
IP address seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 2528 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4492 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1812,i,6925232024119698065,536351442840031,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 4844 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Remittance.htm MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior

Networking

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDNS query: hhid829389.xyz
Source: Joe Sandbox ViewIP Address: 192.0.46.8 192.0.46.8
Source: Joe Sandbox ViewIP Address: 192.0.46.8 192.0.46.8
Source: Joe Sandbox ViewIP Address: 93.184.216.34 93.184.216.34
Source: Joe Sandbox ViewIP Address: 93.184.216.34 93.184.216.34
Source: unknownDNS traffic detected: queries for: hhid829389.xyz
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 07 Feb 2023 14:38:35 GMTServer: ApacheVary: Accept-EncodingLast-Modified: Sun, 18 Jul 2021 22:53:53 GMTX-Frame-Options: DENYX-Content-Type-Options: nosniffReferrer-Policy: same-originExpires: Tue, 07 Feb 2023 15:42:37 GMTX-Content-Type-Options: nosniffAge: 13216Content-Encoding: gzipCache-Control: public, max-age=21603Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;Content-Length: 3177Keep-Alive: timeout=2, max=358Connection: Keep-AliveContent-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 cd 1a db 4e e3 48 f6 19 be a2 c6 33 6a 81 44 70 ee 90 25 44 0a 81 86 6e 7a 18 04 cc ce 74 bf a0 b2 5d 89 0b 1c db 5d 55 0e 9d 5e ad b4 bf b1 bf b7 5f b2 e7 54 d9 8e 93 38 21 d9 41 33 9b 87 b8 ae e7 5e e7 52 76 f7 07 2f 72 d5 34 66 c4 57 e3 a0 b7 db cd 1e 8c 7a bd dd 9d ae e2 2a 60 bd 0f fd 9b 7e 65 4c 43 3a 62 1e b9 63 92 89 09 34 ce a3 31 e5 a1 ec da 66 d1 2e 2c 1f 33 45 89 eb 53 21 99 3a b5 12 35 ac 1c 5b c4 ee 65 33 be 52 71 85 7d 4d f8 e4 d4 1a 44 a1 62 a1 aa 20 72 8b b8 a6 77 6a 29 f6 4d d9 48 c4 49 0e 67 09 4c 48 c7 ec d4 9a 70 f6 12 47 42 15 36 bf 70 4f f9 a7 1e 9b 70 97 55 74 e7 80 f0 90 2b 4e 83 8a 74 69 c0 4e 6b 06 0e 40 0a 78 f8 4c 04 0b 4e 2d a9 a6 01 93 3e 63 00 ca 17 6c 78 6a d9 8f ae Data Ascii: NH3jDp%Dnzt]]U^_T8!A3^Rv/r4fWz*`~eLC:bc41f.,3ES!:5[e3Rq}MDb rwj)MHIgLHpGB6pOpUt+NtiNk@xLN->clxj
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 07 Feb 2023 17:23:15 GMTServer: ApacheLast-Modified: Tue, 05 Oct 2021 16:31:06 GMTContent-Encoding: gzipX-Content-Type-Options: nosniffVary: Accept-EncodingX-Frame-Options: DENYX-Content-Type-Options: nosniffReferrer-Policy: same-originExpires: Tue, 07 Feb 2023 17:51:54 GMTX-Content-Type-Options: nosniffAge: 1881Cache-Control: public, max-age=3600Content-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;Content-Length: 1663Keep-Alive: timeout=2, max=358Connection: Keep-AliveContent-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 c5 59 cd 6e e3 36 10 3e 37 4f c1 ea d0 24 a8 6d 3a ee 22 5d 64 6d 15 de 64 0f 01 b6 46 90 75 2f 2d 8a 80 a6 68 99 89 44 2a 24 65 c7 2d 0a f4 35 fa 7a 7d 92 0e 49 fd d9 d1 66 1d 67 8b 9c 2c 92 33 1f e7 8f 33 43 7a f8 6d 24 a9 59 67 0c 2d 4c 9a 84 07 c3 f2 87 91 28 3c f8 66 68 b8 49 58 78 29 0c 53 82 19 34 d6 9a c7 82 45 68 92 a7 33 a6 34 1a e7 66 21 15 37 eb 21 f6 a4 07 c0 94 32 43 10 5d 10 a5 99 19 05 b9 99 77 df 06 08 87 e5 ca c2 98 ac cb ee 73 be 1c 05 e7 12 a0 85 e9 5a 11 02 44 fd 68 14 18 f6 60 b0 15 e5 5d 85 f3 08 46 90 94 8d 82 25 67 ab 4c 2a d3 60 5e f1 c8 2c 46 11 5b 72 ca ba 6e d0 41 5c 70 c3 49 d2 Data Ascii: Yn6>7O$m:"]dmdFu/-hD*$e-5z}Ifg,33Czm$Yg-L(<fhIXx)S4Eh34f!7!2C]wsZDh`]F%gL*`^,F[rnA\pI
Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKDate: Tue, 07 Feb 2023 17:23:47 GMTServer: ApacheLast-Modified: Sun, 18 Jul 2021 22:53:53 GMTAge: 6971Content-Encoding: gzipX-Content-Type-Options: nosniffVary: Accept-EncodingX-Frame-Options: DENYX-Content-Type-Options: nosniffReferrer-Policy: same-originCache-Control: public, max-age=21603Expires: Tue, 07 Feb 2023 19:23:47 GMTContent-Security-Policy: upgrade-insecure-requests; default-src 'self' https://*.iana.org; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://www.google.com https://cse.google.com https://clients1.google.com; style-src 'self' 'unsafe-inline' https://www.google.com; child-src 'self' https://www.youtube.com https://clients1.google.com https://cse.google.com https://www.google.com/; img-src 'self' https://data.iana.org https://www.iana.org https://www.google.com https://www.googleapis.com https://clients1.google.com https://*.gstatic.com;Content-Length: 2466Keep-Alive: timeout=2, max=358Connection: Keep-AliveContent-Type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 cd 5a db 6e e3 b8 19 be 5e 3f 05 57 5d 0c 12 20 b6 ba 73 55 74 6c 03 69 66 b6 13 2c 36 1b 4c 32 58 a0 37 01 2d d1 16 27 94 a8 21 29 3b de a2 c0 bc 46 81 f6 e5 e6 49 fa fd a4 64 2b b6 e4 d8 2d b0 db dc 58 e2 e1 3f 1f 3e 52 19 8c bf 4d 75 e2 d6 a5 60 99 cb d5 74 30 6e 7e 04 4f a7 83 6f c6 4e 3a 25 a6 6f 75 ce 65 c1 6e 78 2e d8 9d 30 4b 99 08 3b 8e c3 dc 00 ab 72 e1 38 4b 32 6e ac 70 93 a8 72 f3 e1 9f 22 16 4f 9b 99 cc b9 72 28 3e 57 72 39 89 ae 74 e1 44 e1 86 c4 33 62 49 78 9b 44 4e 3c b9 98 78 bf d9 d0 d9 23 53 80 fd 24 5a 4a b1 2a b5 71 ad cd 2b 99 ba 6c 92 0a 92 6b e8 5f 2e 98 2c a4 93 5c 0d 6d c2 95 98 7c 1f e8 80 92 92 c5 23 33 42 4d 22 eb d6 4a d8 4c 08 90 ca 8c 98 4f a2 f8 21 b1 36 7e fd c7 d7 af Data Ascii: Zn^?W] sUtlif,6L2X7-'!);FId+-X?>RMu`t0n~OoN:%ouenx.0K;r8K2npr"Or(>Wr9tD3bIxDN<x#S$ZJ*q+lk_.,\m|#3BM"JLO!6~
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49912 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49912
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?aoul&qrc=glenn.walker@cra-arc.gc.ca HTTP/1.1Host: hhid829389.xyzConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?https://example.com HTTP/1.1Host: href.liConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: example.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: example.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://example.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /domains/example HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_css/2022/iana_website.css HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_js/jquery.js HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_js/iana.js HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/iana-logo-header.svg HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/SourceCodePro-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Bold.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/bookmark_icon.ico HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2015.1/iana-logo-homepage.svg HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /cse.js?cx=010470622406686203020:boq_dnseony HTTP/1.1Host: cse.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKK1yQEIlbbJAQiktskBCMS2yQEIqZ3KAQiUocsBCOC7zAEIm73MAQiywcwBCMXBzAEI1sHMAQ==Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Bold.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /sorry/index?continue=https://cse.google.com/cse.js%3Fcx%3D010470622406686203020:boq_dnseony&q=EgRUETQNGIOSip8GIjBwZeFx4kuwKO0Anr2hOl6B0Jhv87WwRGnV_yxI1B3AmVgNsivYUqSS_Jg7ekQ9qP0yAXI HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CKK1yQEIlbbJAQiktskBCMS2yQEIqZ3KAQiUocsBCOC7zAEIm73MAQiywcwBCMXBzAEI1sHMAQ==Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Regular.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/fonts/NotoSans-Bold.woff HTTP/1.1Host: www.iana.orgConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: http://www.iana.orgsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://www.iana.org/_css/2022/iana_website.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /domains/reserved HTTP/1.1Host: www.iana.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /_img/2022/iana-logo-header.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.iana.org
Source: global trafficHTTP traffic detected: GET /_img/bookmark_icon.ico HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.iana.org
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iana.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /domains HTTP/1.1Host: www.iana.orgConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundAge: 144603Cache-Control: max-age=604800Content-Type: text/html; charset=UTF-8Date: Tue, 07 Feb 2023 17:22:44 GMTExpires: Tue, 14 Feb 2023 17:22:44 GMTLast-Modified: Mon, 06 Feb 2023 01:12:41 GMTServer: ECS (bsa/EB21)Vary: Accept-EncodingX-Cache: 404-HITContent-Length: 1256Connection: close
Source: Remittance.htmString found in binary or memory: https://hhid829389.xyz/?aoul&qrc=glenn.walker
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9

System Summary

barindex
Source: Name includes: Remittance.htmInitial sample: remit
Source: classification engineClassification label: mal48.troj.winHTM@35/0@17/10
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1812,i,6925232024119698065,536351442840031,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Remittance.htm
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1812,i,6925232024119698065,536351442840031,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth5
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration6
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer4
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://hhid829389.xyz/?aoul&qrc=glenn.walker0%Avira URL Cloudsafe
https://hhid829389.xyz/?aoul&qrc=glenn.walker@cra-arc.gc.ca0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
hhid829389.xyz
108.174.197.216
truetrue
    unknown
    accounts.google.com
    216.58.209.45
    truefalse
      high
      cse.google.com
      142.250.180.174
      truefalse
        high
        www.google.com
        142.250.184.100
        truefalse
          high
          clients.l.google.com
          142.250.180.174
          truefalse
            high
            example.com
            93.184.216.34
            truefalse
              high
              ianawww.vip.icann.org
              192.0.46.8
              truefalse
                high
                href.li
                192.0.78.27
                truefalse
                  high
                  www.vip.icann.org
                  192.0.47.7
                  truefalse
                    high
                    clients2.google.com
                    unknown
                    unknownfalse
                      high
                      www.iana.org
                      unknown
                      unknownfalse
                        high
                        pti.icann.org
                        unknown
                        unknownfalse
                          high
                          www.icann.org
                          unknown
                          unknownfalse
                            high
                            NameMaliciousAntivirus DetectionReputation
                            https://www.iana.org/_img/2022/fonts/SourceCodePro-Regular.wofffalse
                              high
                              https://cse.google.com/cse.js?cx=010470622406686203020:boq_dnseonyfalse
                                high
                                https://www.iana.org/_img/2022/iana-logo-header.svgfalse
                                  high
                                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                    high
                                    http://www.iana.org/domains/reservedfalse
                                      high
                                      https://www.google.com/sorry/index?continue=https://cse.google.com/cse.js%3Fcx%3D010470622406686203020:boq_dnseony&q=EgRUETQNGIOSip8GIjBwZeFx4kuwKO0Anr2hOl6B0Jhv87WwRGnV_yxI1B3AmVgNsivYUqSS_Jg7ekQ9qP0yAXIfalse
                                        high
                                        https://www.iana.org/_img/bookmark_icon.icofalse
                                          high
                                          https://www.iana.org/_css/2022/iana_website.cssfalse
                                            high
                                            http://www.iana.org/_img/bookmark_icon.icofalse
                                              high
                                              http://www.iana.org/false
                                                high
                                                http://www.iana.org/domainsfalse
                                                  high
                                                  http://www.iana.org/false
                                                    high
                                                    https://www.iana.org/_img/2022/fonts/NotoSans-Bold.wofffalse
                                                      high
                                                      http://www.iana.org/domains/reservedfalse
                                                        high
                                                        https://example.com/false
                                                          high
                                                          https://href.li/?https://example.comfalse
                                                            high
                                                            https://www.iana.org/_js/iana.jsfalse
                                                              high
                                                              https://www.iana.org/_img/2022/fonts/NotoSans-Regular.wofffalse
                                                                high
                                                                https://example.com/favicon.icofalse
                                                                  high
                                                                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                                                    high
                                                                    http://www.iana.org/_img/2022/iana-logo-header.svgfalse
                                                                      high
                                                                      https://www.iana.org/domains/examplefalse
                                                                        high
                                                                        https://www.iana.org/_img/2015.1/iana-logo-homepage.svgfalse
                                                                          high
                                                                          https://www.iana.org/_js/jquery.jsfalse
                                                                            high
                                                                            https://example.com/false
                                                                              high
                                                                              https://hhid829389.xyz/?aoul&qrc=glenn.walker@cra-arc.gc.cafalse
                                                                              • Avira URL Cloud: safe
                                                                              unknown
                                                                              http://www.iana.org/domainsfalse
                                                                                high
                                                                                NameSourceMaliciousAntivirus DetectionReputation
                                                                                https://hhid829389.xyz/?aoul&qrc=glenn.walkerRemittance.htmfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                • No. of IPs < 25%
                                                                                • 25% < No. of IPs < 50%
                                                                                • 50% < No. of IPs < 75%
                                                                                • 75% < No. of IPs
                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                192.0.46.8
                                                                                ianawww.vip.icann.orgUnited States
                                                                                16876ICANN-DCUSfalse
                                                                                93.184.216.34
                                                                                example.comEuropean Union
                                                                                15133EDGECASTUSfalse
                                                                                108.174.197.216
                                                                                hhid829389.xyzUnited States
                                                                                54290HOSTWINDSUStrue
                                                                                216.58.209.45
                                                                                accounts.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                192.0.78.27
                                                                                href.liUnited States
                                                                                2635AUTOMATTICUSfalse
                                                                                239.255.255.250
                                                                                unknownReserved
                                                                                unknownunknownfalse
                                                                                142.250.184.100
                                                                                www.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                142.250.180.174
                                                                                cse.google.comUnited States
                                                                                15169GOOGLEUSfalse
                                                                                IP
                                                                                192.168.2.1
                                                                                127.0.0.1
                                                                                Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                Analysis ID:800699
                                                                                Start date and time:2023-02-07 18:21:36 +01:00
                                                                                Joe Sandbox Product:CloudBasic
                                                                                Overall analysis duration:0h 7m 36s
                                                                                Hypervisor based Inspection enabled:false
                                                                                Report type:light
                                                                                Cookbook file name:defaultwindowshtmlcookbook.jbs
                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                Number of analysed new started processes analysed:9
                                                                                Number of new started drivers analysed:0
                                                                                Number of existing processes analysed:0
                                                                                Number of existing drivers analysed:0
                                                                                Number of injected processes analysed:0
                                                                                Technologies:
                                                                                • HCA enabled
                                                                                • EGA enabled
                                                                                • HDC enabled
                                                                                • AMSI enabled
                                                                                Analysis Mode:default
                                                                                Analysis stop reason:Timeout
                                                                                Sample file name:Remittance.htm
                                                                                Detection:MAL
                                                                                Classification:mal48.troj.winHTM@35/0@17/10
                                                                                EGA Information:Failed
                                                                                HDC Information:Failed
                                                                                HCA Information:
                                                                                • Successful, ratio: 100%
                                                                                • Number of executed functions: 0
                                                                                • Number of non-executed functions: 0
                                                                                Cookbook Comments:
                                                                                • Found application associated with file extension: .htm
                                                                                • Browse: https://www.iana.org/domains/example
                                                                                • Browse: http://www.iana.org/
                                                                                • Browse: http://www.iana.org/domains
                                                                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, HxTsr.exe, RuntimeBroker.exe, WMIADAP.exe, backgroundTaskHost.exe, conhost.exe
                                                                                • TCP Packets have been reduced to 100
                                                                                • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.163
                                                                                • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, edgedl.me.gvt1.com, login.live.com, tile-service.weather.microsoft.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                No simulations
                                                                                No context
                                                                                No context
                                                                                No context
                                                                                No context
                                                                                No context
                                                                                No created / dropped files found
                                                                                File type:HTML document, ASCII text, with CRLF line terminators
                                                                                Entropy (8bit):5.255051358476731
                                                                                TrID:
                                                                                • HyperText Markup Language (15015/1) 100.00%
                                                                                File name:Remittance.htm
                                                                                File size:225
                                                                                MD5:39bb32548e89f58ceb6960e84791979e
                                                                                SHA1:e70af8a69f739dc0501013a1a9ebb5f4cef552e2
                                                                                SHA256:bf0f39c7f991c76bbd138e4d74dc9cc402aca673c5edd8b6005dc41faf739208
                                                                                SHA512:18764d29c900701e18f6d7b0cf3c9fd59c0cd1a0baab510062a28e91755b5503f1bd979e720d00524ffb0d1c213b30a36a89b22e152cdf9005f925fac4c621b4
                                                                                SSDEEP:6:h4QWqqMzSKcAIK7UK+oSPNKDVjgnEzcTi/MWXfGb:hPlzSb1K0NwVsEzcu/MWPGb
                                                                                TLSH:7AD0A7EB3C50DD056971ACF45C75E22C94B7B2C45E96E217D4C4792B15203B89D471CE
                                                                                File Content Preview:<!DOCTYPE html>..<html>..<body>..<script>..// Javascript URL redirection - generated by www.rapidtables.com..window.location.replace("https://hhid829389.xyz/?aoul&qrc=glenn.walker@cra-arc.gc.ca");..</script>..</body>..</html>
                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                Feb 7, 2023 18:22:37.691319942 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:37.691380024 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:37.691392899 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:37.691487074 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:37.691525936 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:37.691601992 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:37.692004919 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:37.692030907 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:37.692116976 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:37.987829924 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:37.987891912 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:37.987996101 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:37.988661051 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:37.988682985 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:37.988743067 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:37.989568949 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:37.989614010 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:37.990034103 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:37.990087032 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:37.990170002 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:37.990416050 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:37.990466118 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:37.990911961 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:37.990940094 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:37.991348982 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:37.991374016 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:37.991632938 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:37.991652966 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:37.991877079 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:37.991902113 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.138591051 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.159660101 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.159723043 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.160851955 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.160969973 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.163341045 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.163414001 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.166472912 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.196099043 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.198189974 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.233935118 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.291367054 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.291383982 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.296061039 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.363872051 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.379285097 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.379317045 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.379832029 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:38.379885912 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.380006075 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:38.380048990 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.380188942 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.380203962 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.380378008 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.380405903 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.380817890 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.380866051 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.380903006 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.381345034 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.381370068 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.381409883 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.381949902 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.382010937 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.382051945 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:38.382292986 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:38.382379055 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:38.382539988 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.382594109 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:38.382613897 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.383281946 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.383364916 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:38.383384943 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:38.433386087 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.491400003 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:38.491403103 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:38.491410971 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:39.280591965 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:39.280657053 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:39.280733109 CET49702443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:39.280792952 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281105042 CET44349702142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281104088 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281294107 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:39.281342983 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281559944 CET49705443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:39.281610012 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281779051 CET49708443192.168.2.5142.250.180.174
                                                                                Feb 7, 2023 18:22:39.281809092 CET44349708142.250.180.174192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281836987 CET44349705108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:39.281837940 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:39.282054901 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:39.282099962 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:39.282169104 CET49707443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:39.282188892 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:39.282314062 CET44349707216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:39.282712936 CET44349703216.58.209.45192.168.2.5
                                                                                Feb 7, 2023 18:22:39.287015915 CET49709443192.168.2.5108.174.197.216
                                                                                Feb 7, 2023 18:22:39.287077904 CET44349709108.174.197.216192.168.2.5
                                                                                Feb 7, 2023 18:22:39.287311077 CET49703443192.168.2.5216.58.209.45
                                                                                Feb 7, 2023 18:22:39.287374020 CET44349703216.58.209.45192.168.2.5
                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                Feb 7, 2023 18:22:36.930655003 CET4972453192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:36.930768967 CET6145253192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:36.930810928 CET6532353192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:36.948674917 CET53497248.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:36.958616972 CET53614528.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:36.958682060 CET53653238.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:39.745507956 CET5503953192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:39.763851881 CET53550398.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:41.076035023 CET5922053192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:41.095607996 CET53592208.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:41.445427895 CET5506853192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:41.464953899 CET53550688.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:53.454372883 CET5626353192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:53.474816084 CET53562638.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:56.124258041 CET6441953192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:56.142252922 CET53644198.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:22:56.820790052 CET6134453192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:22:57.012938976 CET53613448.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:23:06.101645947 CET6028453192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:23:06.121783018 CET53602848.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:23:15.503917933 CET5355553192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:23:15.522234917 CET53535558.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:23:39.830362082 CET5887253192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:23:39.848680973 CET53588728.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:23:55.121695995 CET5197253192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:23:55.141412973 CET53519728.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:23:58.891067028 CET5572653192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:23:58.891454935 CET5792453192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:23:58.911197901 CET53579248.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:23:59.056502104 CET53557268.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:25:00.620471001 CET6179753192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:25:00.638747931 CET53617978.8.8.8192.168.2.5
                                                                                Feb 7, 2023 18:25:39.995788097 CET5287453192.168.2.58.8.8.8
                                                                                Feb 7, 2023 18:25:40.015918016 CET53528748.8.8.8192.168.2.5
                                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                Feb 7, 2023 18:22:36.930655003 CET192.168.2.58.8.8.80xe34eStandard query (0)hhid829389.xyzA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:36.930768967 CET192.168.2.58.8.8.80x5cf3Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:36.930810928 CET192.168.2.58.8.8.80xe230Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:39.745507956 CET192.168.2.58.8.8.80xe70Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:41.076035023 CET192.168.2.58.8.8.80xd5cfStandard query (0)href.liA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:41.445427895 CET192.168.2.58.8.8.80xd3a0Standard query (0)example.comA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:53.454372883 CET192.168.2.58.8.8.80xd346Standard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:56.124258041 CET192.168.2.58.8.8.80x7e39Standard query (0)www.icann.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:56.820790052 CET192.168.2.58.8.8.80x62e4Standard query (0)pti.icann.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:06.101645947 CET192.168.2.58.8.8.80x3186Standard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:15.503917933 CET192.168.2.58.8.8.80xef68Standard query (0)cse.google.comA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:39.830362082 CET192.168.2.58.8.8.80xc764Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:55.121695995 CET192.168.2.58.8.8.80x4755Standard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:58.891067028 CET192.168.2.58.8.8.80xe243Standard query (0)pti.icann.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:58.891454935 CET192.168.2.58.8.8.80xa7bbStandard query (0)www.icann.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:25:00.620471001 CET192.168.2.58.8.8.80x10d3Standard query (0)www.iana.orgA (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:25:39.995788097 CET192.168.2.58.8.8.80x7e89Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                Feb 7, 2023 18:22:36.948674917 CET8.8.8.8192.168.2.50xe34eNo error (0)hhid829389.xyz108.174.197.216A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:36.958616972 CET8.8.8.8192.168.2.50x5cf3No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:36.958682060 CET8.8.8.8192.168.2.50xe230No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:36.958682060 CET8.8.8.8192.168.2.50xe230No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:39.763851881 CET8.8.8.8192.168.2.50xe70No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:41.095607996 CET8.8.8.8192.168.2.50xd5cfNo error (0)href.li192.0.78.27A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:41.095607996 CET8.8.8.8192.168.2.50xd5cfNo error (0)href.li192.0.78.26A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:41.464953899 CET8.8.8.8192.168.2.50xd3a0No error (0)example.com93.184.216.34A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:53.474816084 CET8.8.8.8192.168.2.50xd346No error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:53.474816084 CET8.8.8.8192.168.2.50xd346No error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:56.142252922 CET8.8.8.8192.168.2.50x7e39No error (0)www.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:56.142252922 CET8.8.8.8192.168.2.50x7e39No error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:57.012938976 CET8.8.8.8192.168.2.50x62e4No error (0)pti.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:22:57.012938976 CET8.8.8.8192.168.2.50x62e4No error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:06.121783018 CET8.8.8.8192.168.2.50x3186No error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:06.121783018 CET8.8.8.8192.168.2.50x3186No error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:15.522234917 CET8.8.8.8192.168.2.50xef68No error (0)cse.google.com142.250.180.174A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:39.848680973 CET8.8.8.8192.168.2.50xc764No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:55.141412973 CET8.8.8.8192.168.2.50x4755No error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:55.141412973 CET8.8.8.8192.168.2.50x4755No error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:58.911197901 CET8.8.8.8192.168.2.50xa7bbNo error (0)www.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:58.911197901 CET8.8.8.8192.168.2.50xa7bbNo error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:59.056502104 CET8.8.8.8192.168.2.50xe243No error (0)pti.icann.orgwww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:23:59.056502104 CET8.8.8.8192.168.2.50xe243No error (0)www.vip.icann.org192.0.47.7A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:25:00.638747931 CET8.8.8.8192.168.2.50x10d3No error (0)www.iana.orgianawww.vip.icann.orgCNAME (Canonical name)IN (0x0001)false
                                                                                Feb 7, 2023 18:25:00.638747931 CET8.8.8.8192.168.2.50x10d3No error (0)ianawww.vip.icann.org192.0.46.8A (IP address)IN (0x0001)false
                                                                                Feb 7, 2023 18:25:40.015918016 CET8.8.8.8192.168.2.50x7e89No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                                                                • clients2.google.com
                                                                                • hhid829389.xyz
                                                                                • accounts.google.com
                                                                                • href.li
                                                                                • example.com
                                                                                • https:
                                                                                  • www.iana.org
                                                                                • cse.google.com
                                                                                • www.google.com

                                                                                Click to jump to process

                                                                                Target ID:0
                                                                                Start time:18:22:32
                                                                                Start date:07/02/2023
                                                                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                                                                Imagebase:0x7ff7d31b0000
                                                                                File size:2851656 bytes
                                                                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                Target ID:1
                                                                                Start time:18:22:34
                                                                                Start date:07/02/2023
                                                                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1952 --field-trial-handle=1812,i,6925232024119698065,536351442840031,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                                                Imagebase:0x7ff7d31b0000
                                                                                File size:2851656 bytes
                                                                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                Target ID:2
                                                                                Start time:18:22:35
                                                                                Start date:07/02/2023
                                                                                Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                Wow64 process (32bit):false
                                                                                Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Remittance.htm
                                                                                Imagebase:0x7ff7d31b0000
                                                                                File size:2851656 bytes
                                                                                MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                                                                Has elevated privileges:true
                                                                                Has administrator privileges:true
                                                                                Programmed in:C, C++ or other language
                                                                                Reputation:high

                                                                                No disassembly